IBMDO YOU?Hi, I'm MBO!

Settings

Make the site feel at home on your screen.

Theme

Loading your theme preference.

Keyboard shortcuts

Open search from anywhere, then move through the results without leaving the keyboard.

Open settings
Ctrl,or⌘,
Open search
CtrlKor⌘K
Select a search result
↑↓
Open the selected result
Enter
Close an open dialog
Esc

Linux

Use the OpenSSH client on Linux

Connect to Linux servers with OpenSSH, use protected key pairs and ssh-agent, and create readable per-host client configuration.

OpenSSH is the standard command-line tool for opening an encrypted shell or running a command on a remote Linux server. The client supports passwords and several stronger authentication methods, including public-key authentication.

Make a basic connection

Supply the remote account followed by the server name:

ssh user@server.example.com

On the first connection, SSH displays the server's host-key fingerprint. Verify that fingerprint with the server administrator or another trusted source before accepting it. The host key proves which server you reached; accepting an unverified key leaves room for a machine-in-the-middle attack.

Once accepted, the host key is recorded in ~/.ssh/known_hosts. SSH warns and refuses normal authentication if that identity later changes unexpectedly. Investigate that warning instead of deleting the old entry automatically.

The server decides which authentication methods it permits. If password authentication is enabled and no suitable key is available, the client may ask for the remote account's password.

Connect with a key pair

Public-key authentication uses two related files:

  • The public key is installed for the remote account, normally in ~/.ssh/authorized_keys on the server.
  • The private key remains on the client and proves possession of the key pair. It must not be shared.

Create a dedicated Ed25519 key pair and set a passphrase when prompted:

ssh-keygen -t ed25519 -f ~/.ssh/work-example -C "work-example"

This produces the private key ~/.ssh/work-example and public key ~/.ssh/work-example.pub. If the server temporarily permits password authentication and ssh-copy-id is installed, append the public key to the remote account with:

ssh-copy-id -i ~/.ssh/work-example.pub user@server.example.com

Otherwise, give the .pub file to the server administrator through an approved channel. Never send the private-key file.

Select a private key for one connection with -i:

ssh -i ~/.ssh/work-example user@server.example.com

SSH asks for the key's passphrase before it can use the private key.

Use ssh-agent

ssh-agent keeps unlocked identities available to SSH clients, so a passphrase-protected key does not need to be unlocked for every connection. Desktop and login environments often start an agent already. Check for its socket first:

printf '%s\n' "$SSH_AUTH_SOCK"

If no agent is available, start one for the current shell:

eval "$(ssh-agent -s)"

Add the key with a one-hour lifetime:

ssh-add -t 1h ~/.ssh/work-example

List the public fingerprints of loaded identities:

ssh-add -l

Remove one key when it is no longer needed:

ssh-add -d ~/.ssh/work-example

Remove every loaded identity with:

ssh-add -D

If you started a dedicated agent for this shell, stop it when finished:

eval "$(ssh-agent -k)"

The agent does not hand the private-key material to SSH, but a process that can access the agent socket may ask it to perform authentication operations while the key is loaded. Use passphrases, short agent lifetimes and a locked screen, and avoid forwarding the agent to remote systems unless there is a reviewed need.

Configure frequently used hosts

The per-user client configuration is ~/.ssh/config. Create the directory and file with restrictive permissions:

mkdir -p ~/.ssh
chmod 700 ~/.ssh
touch ~/.ssh/config
chmod 600 ~/.ssh/config

Add a memorable alias for the server:

Host work-example
  HostName server.example.com
  User user
  IdentityFile ~/.ssh/work-example
  IdentitiesOnly yes
  UserKnownHostsFile ~/.ssh/work-example_known_hosts
 
Host *
  ServerAliveInterval 15
  ServerAliveCountMax 3

You can now connect using only the alias:

ssh work-example

The settings mean:

  • Host work-example defines the name typed on the command line.
  • HostName supplies the real DNS name or address.
  • User selects the remote account.
  • IdentityFile selects the private key.
  • IdentitiesOnly yes prevents unrelated agent keys from being offered to this server.
  • UserKnownHostsFile keeps this server's host identity in a dedicated file.
  • ServerAliveInterval 15 requests an encrypted keepalive after 15 seconds without received data.
  • ServerAliveCountMax 3 disconnects after three unanswered keepalives.

OpenSSH uses the first value it finds for most settings, so put specific Host blocks before the final Host * defaults. Host patterns also work when several servers share a configuration:

Host *.example.com
  User myuser
  IdentityFile ~/.ssh/work-example
  IdentitiesOnly yes

Inspect the fully evaluated settings without making a connection:

ssh -G work-example

For connection troubleshooting, increase client logging temporarily:

ssh -v work-example

Add a second or third v only when more detail is needed. Debug output can include hostnames, account names and connection details, so review it before sharing.

The current OpenSSH manuals document the complete ssh command, ssh_config options, ssh-agent and ssh-add behaviour.

Find the fix

Search articles

Esc

Search titles, technical terms or error codes.